Executive brief
A security vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to convince a user to open a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.
Technical details
A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC, and Microsoft 365 Apps. The flaw allows a local attacker to disclose sensitive information by leveraging uninitialized memory resources. Exploitation requires user interaction, typically involving the victim opening a malicious file. Successful exploitation results in a high impact on confidentiality but does not affect integrity or availability. Microsoft has released security updates to address this issue across affected platforms.
Affected products
- Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
- Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
- Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
- Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
- Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
- Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
- Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory